MikeTrendsTrends right now

search

open source security community

Trends

  1. 1
    Several vulnerabilities discovered in the Linux kernelβ–ΌSeveral vulnerabilities have been discovered in the Linux kernelYhnTechnologyCybersecurity57930 min ago

    New security flaws have been found in the Linux kernel, prompting attention from the open-source community and system administrators who rely on the widely used operating system core. Newly reported kernel vulnerabilities typically lead to patch releases and updates across distributions. Details of the affected versions and the severity of the flaws have not been specified beyond the announcement.

  2. 2
    Google pauses bug bounty submissions for open-source software●Google stellt Bug-Bounty-Programm fΓΌr Open Source vorerst ein Google nimmt seit 1. Oktober im Bug-Bounty-Programm fΓΌr OpMmastodonTechnologySoftware121 d ago

    Google has stopped accepting vulnerability reports for open-source software through its bug bounty program as of October 1. The company will temporarily no longer pay rewards for product flaws found in open-source projects, though reports on its own flagship products continue. The move is drawing attention in the security community, as the open-source incentive program was seen as an important way to support researchers auditing widely used projects.

  3. 3
    Greg Kroah-Hartman on security in the age of LLMs●Greg Kroah-Hartman – Security in the LLM Age [video]YhnTechnologyAI3421 h ago

    A recorded talk by Linux kernel developer Greg Kroah-Hartman examines how large language models are affecting software security. Kroah-Hartman, who has long maintained kernel stable releases and driven the kernel's code-of-conduct and driver work, discusses the risks and implications of AI-generated code entering critical open-source infrastructure. The talk is drawing attention among developers weighing how LLM tooling should be handled in security-sensitive codebases.

  4. 4
    XOrg Server and Xwayland security updates patch multiple flaws●Multiple # Security Issues Patched in XOrg Server 21.1.25 and Xwayland 24.1.14, Update Now https:// 9to5linux.com/multipMmastodonTechnologyCybersecurity66 h ago

    New releases of XOrg Server 21.1.25 and Xwayland 24.1.14 patch multiple security vulnerabilities, and users are being urged to update their systems as soon as possible. The announcement is drawing attention in the Linux and open-source community, where these components are widely used to handle graphics display duties on Linux desktop systems.

  5. 5
    LSU Cyber Team Wins $750K from NSA for Digital Forensics Toolβ–ΌLSU Cyber Team Releases First Open-Source Tool to Recover Fragmented Digital Evidence at Scale, Solves Two 20-year-old Grand Challenges, Wins $750K from NSAβœ‰newsTechnologySoftware4 h ago

    A Louisiana State University cybersecurity team has released the first open-source tool capable of recovering fragmented digital evidence at scale, solving two longstanding 'grand challenges' in digital forensics that have remained open for roughly 20 years. The work has earned the team a $750,000 award from the National Security Agency, and the tool is now freely available for forensic investigators and researchers.

  6. 6
    OpenSSF Announces Expanded Membership and Global Policy Resources in Europeβ–ΌOpenSSF Shares Expanded Membership and New Global Policy Resources During Community Day Europeβœ‰newsTechnologySoftware13 h ago

    The Open Source Security Foundation (OpenSSF) announced expanded membership and new global policy resources during its Community Day Europe event. The announcement, distributed by the Linux Foundation via PR Newswire, highlights the foundation's growing base of participating organizations and its effort to provide guidance on open source security policy worldwide. Further details about the new members and resources were not included in available coverage.

  7. 7

    Debate is underway over who actually controls and profits from open source software, as major companies increasingly fund, contribute to and commercialize community-built projects. Commenters are weighing whether corporate backing undermines the open source model or secures its future, and whether maintainers get a fair share of the value they create.

  8. 8
    NetBSD works to stabilize the Racoon2 IKE daemon●Improving and Stabilizing the Racoon2 IKE Daemon in NetBSDYhn1510 h ago

    The NetBSD Project has published a write-up on efforts to improve and stabilize the Racoon2 IKE daemon, the component that handles Internet Key Exchange for setting up secure IPsec connections. The post outlines ongoing work to make the long-standing daemon more reliable, and it is drawing attention from developers interested in networking security and open-source systems work.

  9. 9
    Parrot OS 7.4 Released With Linux Kernel 7.1 and AnonSurf 6.0●Parrot OS 7.4 rolls out with Linux kernel 7.1, AnonSurf 6.0, refreshed security tools, updated Raspberry Pi images, andMmastodonTechnologySoftware44 d ago

    The Parrot security team has released Parrot OS 7.4, a point update to its privacy-focused Linux distribution. The release ships with Linux kernel 7.1, the new AnonSurf 6.0 anonymity tool, refreshed security and penetration testing utilities, updated Raspberry Pi images, and broader package improvements. Users in the Linux and open-source community are welcoming the update for keeping the distro's privacy tooling current.

  10. 10
    Google Pauses Open-Source Bug Bounty Programβ–ΌGoogle Pauses Open-Source Bug Bounty Program Amid AI Slopβœ‰newsTechnologySoftware8 h ago

    Google has paused its open-source bug bounty program, with reports attributing the decision to a flood of low-quality, AI-generated vulnerability reports overwhelming the program's reviewers. The move highlights a growing burden on security teams as automated tools churn out submissions that must be triaged. Security commentators are debating whether the change signals wider trouble for crowd-sourced vulnerability disclosure.

  11. 11
    Google suspends part of its open source bug bountyβ–ΌWhy Google is suspending part of its open source bug bountyβœ‰newsTechnologySoftware13 h ago

    Google is suspending part of its bug bounty program covering open source projects. The move means security researchers will temporarily no longer be rewarded for reporting certain vulnerabilities in Google's open source software. The announcement is drawing attention from the security community, with researchers questioning the implications for vulnerability disclosure and Google's commitment to open source security.

  12. 12
    testers try out open-source project LittleFedi●Got the honors to help testing LittleFedi, an # opensource project by @ stefano and a very interesting one! Why? Small,MmastodonTechnologySoftware44 d ago

    A security community member has been helping test LittleFedi, an open-source project developed by Stefano. Early impressions highlight the software's simplicity: small, focused and free of clutter, with an interface that is easy to use. The tester also praised Stefano for taking user feedback on board and improving the project accordingly. The post invites others to set the software up themselves.

  13. 13
    Google Winds Down Part of Its Open Source Bounty Programβ–ΌGoogle Has Shut Down Part of its Open Source Bounty Programβœ‰newsTechnologySoftware2 h ago

    Google has shut down part of its open source bounty program, which paid researchers and developers for improving open source projects. The move affects a program that had rewarded security fixes and contributions to community-driven software. It is the latest in a series of cost-cutting measures at the company, and open source advocates have criticised the decision as a step back from Google's support for the community.

  14. 14
    Nous Research raises $90M at $1.5B valuationβ–ΌNous Research raises $90M at $1.5B valuation for open-source AIβœ‰newsTechnologySoftware2 h ago

    Nous Research has raised $90 million in funding at a $1.5 billion valuation to advance its open-source AI work. The deal marks a significant milestone for the startup, which builds open models as an alternative to closed systems from major AI labs. The funding signals continued strong investor appetite for open-source artificial intelligence companies.

  15. 15
    Securing the Open Source AI Ecosystemβ–ΌSecuring the Open Source AI Ecosystem with Pranshu Raghavβœ‰newsTechnologySoftware1 d ago

    HackerNoon has published an interview with Pranshu Raghav on securing the open source AI ecosystem. The piece examines how developers and security teams can protect openly available AI models, tools and pipelines from misuse and vulnerabilities as adoption of open AI projects accelerates across the software industry.

  16. 16
    Google pauses open source bug bounty amid flood of AI reportsβ–ΌGoogle benches open source bug bounty program following β€˜significant rise’ in AI submissionsβœ‰newsTechnologySoftware1 d ago

    Google has suspended its open source bug bounty program, citing a significant rise in AI-generated vulnerability submissions. The company says many of the reports flooding in are low-quality, machine-written findings that take up valuable reviewer time without adding real security value. The move has sparked debate among security researchers about the impact of automated tools on responsible disclosure programs and how bounty platforms should handle AI-created noise.

  17. 17
    OpenVPN 2.7.8 Released with Security Fixes●# OpenVPN 2.7.8 Released with Security and Bug Fixes, Various Improvements https:// 9to5linux.com/openvpn-2-7-8-re leaseMmastodonTechnologySoftware15 h ago

    The OpenVPN project has released version 2.7.8 of its widely used open-source VPN software. The update delivers security fixes alongside bug fixes and various improvements, and is available for Linux and other platforms. Open-source community members are sharing the release, encouraging users of the popular VPN tool to update their installations.

  18. 18
    Google Freezes Open Source Bug Bounty Until 2027 Amid AI Spam Floodβ–ΌGoogle Freezes Open Source Bug Bounty Until 2027 Due to AI Spam Floodβœ‰newsTechnologySoftware1 d ago

    Google has paused its open source bug bounty programme until 2027, citing an overwhelming flood of AI-generated spam reports. Invalid, low-quality vulnerability submissions allegedly produced by AI tools have crowded out legitimate security research, making the programme unsustainable in its current form. The move has sparked debate in the security community about how AI is affecting vulnerability disclosure processes and whether other bounty programmes will follow suit.

  19. 19
    Sherpa Intelligence Releases October 7 Security Briefing●Basecamp Briefing for October 7th πŸ”οΈ # InfoSec , # GRC , # OSINT and more curated for you by Sherpa Intelligence: Your GMmastodonTechnologyCybersecurity36 h ago

    Sherpa Intelligence has published its Basecamp Briefing for October 7th, a curated roundup covering information security, governance, risk and compliance, and open-source intelligence topics. The briefing is part of the firm's regular effort to package key cybersecurity developments into one digest for practitioners.

  20. 20
    CIRCL launches major website update with new feeds●We did a major update to our website: https://www. circl.lu/ There are now RSS and Atom feeds available: https://www. ciMmastodonTechnologySoftware73 d ago

    CIRCL, Luxembourg's national cybersecurity agency, has rolled out a major redesign of its website. The update adds RSS and Atom feeds for following its content, plus a complete overview page listing all of the organisation's open-source and open-standard projects. The announcement is drawing attention from the cybersecurity and open-source community, which closely follows CIRCL's freely available tools and resources.

  21. 21
    Free Breach-Check Alternatives to Have I Been Pwned in 2026●By Marcus Hale. Originally published on Meikuio on August 7, 2026. Reviewed for syndication October... # security # privMmastodonTechnologySoftware31 d ago

    A new guide by Marcus Hale, first published on Meikuio in August 2026 and recently reviewed for syndication, surveys free alternatives to Have I Been Pwned, the popular service for checking whether your email or credentials have appeared in data breaches. The piece covers open-source options aimed at beginners, with attention to security and privacy trade-offs, and is being shared widely in developer and open-source communities.

  22. 22
    OpenSSH Creator's Security Philosophy Draws Renewed Attention●OpenSSH Ships on Every Mac, Linux Server and Windows. Its Creator Trusts No One https://zbruceli.org/blog/the-man-who-trMmastodonTechnologySoftware31 d ago

    A profile of the OpenSSH project and its creator is drawing attention across the tech community. OpenSSH underpins secure remote access on virtually every Mac, Linux server and Windows machine, yet is maintained with a deliberately paranoid approach: its code is written to trust no input, no system and no contributor. The piece highlights how this rigour has kept the critical open-source tool safe for decades, prompting discussion about whether other widely used software should adopt similar discipline.

  23. 23
    RetireTui brings retirement planning to the terminal●When am I retiring? One sec, let me check my terminal... πŸ“ˆ RetireTui β€” See your financial future from the terminal πŸ₯Ά A lMmastodonBusinessFinance42 d ago

    A developer has released RetireTui, a local-first retirement planning tool that runs in the terminal. Written in Rust, it offers year-by-year financial projections, tax calculations, historical market data and Social Security optimization, with all data kept on the user's own machine. The project is drawing attention in open-source and developer communities for its unusual terminal-based take on personal finance software.

  24. 24
    Payload CMS vulnerability could expose hidden fieldsβ—πŸš¨ EUVD-2026-93489 πŸ“Š Score: 7.1/10 (CVSS v3.1) πŸ“¦ Product: payload, payload 🏒 Vendor: payloadcms πŸ“… Updated: 2026-10-06 πŸ“ PMmastodonTechnologyCybersecurity01 d ago

    A medium-severity vulnerability, EUVD-2026-93489, has been documented in Payload CMS, the open-source content platform by Payload. Rated 7.1 out of 10 on the CVSS v3.1 scale, the flaw involves polymorphic join queries that could disclose hidden fields. The advisory was updated on 6 October 2026, and security feeds are circulating the details.

  25. 25
    LibreOffice and OpenOffice flaws let malicious spreadsheets run code●The first one has been patched. The Hacker News: LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code WiMmastodonTechnologyCybersecurity11 d ago

    Security researchers have disclosed vulnerabilities in LibreOffice and OpenOffice that allow malicious spreadsheet files to execute code on a victim's machine without triggering the usual macro warnings. The first of the flaws has reportedly been patched, and users are being urged to update their office suites. The issue has drawn attention in the open-source and information security communities because it bypasses a long-standing protection that many users rely on when opening documents from unknown sources.

  26. 26
    Developer Launches Self-Custodial Multi-Chain Wallet Bot for Telegram●Hey everyone, I recently built VaultForgeWalletBot β€” a self-custodial multi-chain crypto wallet... # crypto # telegram #MmastodonBusinessCrypto23 d ago

    An independent developer has built VaultForgeWalletBot, a self-custodial, multi-chain crypto wallet that operates inside Telegram, and published an account of how it was made. The project is open source and is being shared with crypto and software development communities. Interest centers on the unusual approach of combining self-custody of digital assets with a messaging app, a design that raises both convenience and security questions.

  27. 27
    AI Finds More Vulnerabilities, But Open Source Lacks Manpowerβ–ΌAI is Finding More Vulnerabilities But Open Source Needs More People tβœ‰newsTechnologySoftware5 d ago

    AI tools are increasingly effective at discovering software vulnerabilities, but security experts warn that open source projects still lack the human maintainers needed to review, triage and fix the growing volume of reported flaws. Infosecurity Magazine highlights the widening gap between machine-generated bug reports and the limited developer capacity available to address them across widely used open source components.

  28. 28
    CryptPad's C trust score flags unpatched vulnerabilities●CryptPad holds a C trust score despite just 4 CVEs. The problem is 75% remain unpatched, with one high-severity flaw atMmastodonTechnologyCybersecurity01 d ago

    CryptPad, the open-source collaborative document platform, has received a C trust score in a vendor security assessment. The rating reflects not the small number of reported vulnerabilities β€” just four CVEs β€” but the fact that roughly 75% of them remain unpatched, including one high-severity flaw rated 7.5 on the CVSS scale. Security commentators argue that low CVE counts mean little if fixes lag behind disclosures.

  29. 29
    Infosec newcomer introduces themselves on Mastodonβ–ΌHello Mastodon! I'm into Computer # Security , # Programming , # ReverseEngineering , # Hacking , # Linux , # AmateurRadMmastodonTechnologyCybersecurity175 d ago

    A newcomer has introduced themselves to Mastodon's infosec community, listing interests including computer security, programming, reverse engineering, hacking, Linux, cryptography, privacy, open source and amateur radio, with a focus on technology that helps people communicate. The post is drawing modest engagement from the security-focused corner of the decentralized social network.

  30. 30
    Privacy-minded users question Proton Mail's ethicsβ–ΌBeen hearing some sketchy things about the ethics going on at # protonmail and after I just finished my gmail transitionMmastodonLifeHome & Garden74 d ago

    Users in the open-source community are voicing concerns about ethical practices at Proton Mail, the Swiss privacy-focused email provider. Some say they had just switched from Google's Gmail only to hear worrying claims, and are now asking peers what alternatives to use for email and cloud storage, with suggestions including self-hosted options like Nextcloud.

  31. 31
    Developer launches first mobile app after taxi kidnapping ordeal●Yes, the title is correct. This is really what happened to me, and today I'm going to write about... # mobile # softwareMmastodonTechnologySoftware24 d ago

    A software developer says they have launched their first mobile application after surviving a kidnapping involving a taxi, and is now writing publicly about the experience. The post has drawn attention across mobile, security and open-source communities, with readers responding to the unusual link between a personal safety incident and the decision to build and release an app.

  32. 32
    Google Suspends Open Source Bug Bounty Program Over AI-Generated Reportsβ–ΌGoogle Suspends Open Source Bug Bounty Program Due to Surge in AI-Generated Reportsβœ‰newsTechnologySoftware2 d ago

    Google has suspended its open source bug bounty program, citing a flood of AI-generated vulnerability reports. The company says low-quality, automated submissions have overwhelmed reviewers, making it hard to identify genuine security flaws. Security researchers say the incident highlights how generative AI tools are producing mass, superficial bug reports that undermine trusted vulnerability disclosure programs.

  33. 33
    SELinux: a security tool born of paranoia●Rulers from the most paranoid realms develop useful weapons. # Linux # OpenSource https:// cromwell-intl.com/open-sourceMmastodonTechnologySoftware22 d ago

    A write-up on SELinux is circulating among Linux and open-source users, framing the US National Security Agency's security enhancements for Linux as 'weapons' built by the world's most paranoid rulers. The article covers how Security-Enhanced Linux works across RHEL, Oracle Linux, CentOS and related distributions, and why the mandatory access controls originally developed with the NSA are now considered a useful defense tool.

  34. 34
    AI Finds More Software Vulnerabilities, But Open Source Fixers Are Scarceβ–ΌAI is Finding More Vulnerabilities But Open Source Needs More People to Fix Themβœ‰newsTechnologySoftware4 d ago

    AI tools are increasingly effective at discovering software vulnerabilities, including many in open source projects. However, the pool of human developers able to review, verify and patch these flaws is not keeping pace, leaving security gaps open longer. The report argues that discovery is outstripping remediation capacity, and calls for more investment in open source maintenance and the people who sustain it.

  35. 35
    Pangolin 1.24 Adds Exit Nodes and Linux Subnet Routing●Pangolin 1.24 introduces full-tunnel Exit Nodes, Linux Subnet Router support, and major client improvements across desktMmastodonTechnologySoftware23 d ago

    The open-source tunneled reverse proxy Pangolin has released version 1.24, bringing full-tunnel Exit Nodes, support for Linux Subnet Routers, and significant client improvements across desktop and mobile platforms. The update extends Pangolin's capabilities as a self-hosted alternative for secure remote access, drawing attention from the open-source and VPN communities.

  36. 36
    Civil society groups automate their work on Cloudflare●Building for good: How civil society organizations are automating on Cloudflare https://blog.cloudflare.com/civil-societMmastodonTechnology35 d ago

    Cloudflare has published a blog post outlining how civil society organizations are using its platform to automate their operations. The piece highlights ways nonprofits and advocacy groups apply automation tools for security, reliability and efficiency in their work. The story is circulating among technology and open-source communities online.

  37. 37
    No-KYC privacy directory with incident-based trust scoring released●I built a no-KYC privacy directory with incident-based trust scoring (and a map of who's been sanctioned) # privacy # seMmastodonTechnologySoftware34 d ago

    An open-source developer has released a privacy directory that requires no identity verification, instead ranking participants with a scoring system based on recorded incidents. The project also includes a map showing which parties have been sanctioned. It is written in PHP and shared with the coding community as free software, with discussion so far centered on privacy, security, and whether incident-based trust can replace conventional verification.

  38. 38
    Sovereign Tech Fund relaunches resilience programme for open source●Wir starten das # SovereignTechResilience Programm neu mit vier weiteren Dienstleistungen fΓΌr kritische # OpenSource -PrMmastodonTechnologySoftware66 d ago

    Germany's Sovereign Tech Fund is relaunching its Sovereign Tech Resilience programme, adding four new services for critical open source projects: memory safety, post-quantum encryption, software supply chain security, and compliance with the EU Cyber Resilience Act. The move aims to strengthen the security and long-term maintenance of digital infrastructure that many public and private systems rely on.

  39. 39
    Tanuki open-source tool brings protocol-first Linux AD triage to AI agents●Excited to share a new open-source project: Tanuki 🦝 Protocol-first Linux Active Directory triage for AI coding agents &MmastodonTechnologyCybersecurity24 d ago

    A security researcher has released Tanuki, a new open-source tool described as protocol-first Linux Active Directory triage built for AI coding agents and operators. The developer says most coding agents hallucinate or propose noisy, dangerous tactics when handling Linux AD environments, such as recommending weak crypto settings. The project is being shared with the infosec community.

  40. 40
    Parrot OS 7.4 Released with AnonSurf 6.0 and New Raspberry Pi Imagesβ—πŸ§ Parrot OS 7.4 Released with AnonSurf 6.0, Updated Raspberry Pi Images Parrot OS 7.4 security-oriented distribution isMmastodonTechnologyAI14 d ago

    The Parrot Security team has released Parrot OS 7.4, the latest update to its security and privacy-focused Linux distribution. Version 7.4 ships with AnonSurf 6.0, updated hacking and security tools, optimized builds, and refreshed Raspberry Pi and ARM images, and is now available for download. Linux enthusiasts and privacy-focused users are welcoming the release and discussing the changes it brings.

Repos